Splunk Enterprise

Search History not loading on one node

PapayaPower
Observer

I've currently got an issue where my search history wont load on one particular search head. As far as I know, it's only affecting me. Our search heads are clustered, and it's only affecting 1 of the 3 nodes, we're currently on 9.3. When I try to load the search history it just says "Waiting for results...".

I can work around it, but it bothers me that it's something that's not working and I've not yet been able to solve.

Things I've tried:

  • Different browser of course.
  • Cluster status shows as being up to date and replication being A-OK.
  • Compared my KVStore across all three nodes and they appear identical.
  • Checked log files but I can't see anything obvious.

Most of the troubleshooting help I've found online all seems to assume you're using a single search head.

Looking for some inspiration on what to try next! 

Labels (1)
0 Karma
Get Updates on the Splunk Community!

New Year, New Changes for Splunk Certifications

As we embrace a new year, we’re making a small but important update to the Splunk Certification ...

[Puzzles] Solve, Learn, Repeat: Unmerging HTML Tables

[Puzzles] Solve, Learn, Repeat: Unmerging HTML TablesFor a previous puzzle, I needed some sample data, and ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...